Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
220 results
weaponised-XSS-payloads preview

weaponised-XSS-payloads

GitHubhakluke/weaponised-xss-payloads

XSS payloads designed to turn alert(1) into P1

exploitationpayload-developmentpayload-generation+3
1.4k
3 years ago
COFFLoader preview

COFFLoader

GitHubtrustedsec/coffloader

Run Beacon Object Files (BOFs) outside Cobalt Strike by parsing 64-bit COFF object files, with Beacon-compatible argument generation and helper…

binary-analysispayload-developmentpenetration-testing+2
6527 days ago
go-shellcode preview

go-shellcode

GitHubne0nd0g/go-shellcode

A repository of Windows Shellcode runners and supporting utilities. The applications load and execute Shellcode using various API calls or techniques.

exploitationpayload-developmentpayload-generation+4
1.2k4 years ago
FakeImageExploiter preview

FakeImageExploiter

GitHubr00t-3xp10it/fakeimageexploiter

Use a Fake image.jpg to exploit targets (hide known file extensions)

command-and-controlexploitationpayload-development+5
9471 year ago
CVE-2021-3156 preview

CVE-2021-3156

GitHubblasty/cve-2021-3156

Exploit for CVE-2021-3156 (Baron Samedit), a heap-based buffer overflow in sudo, enabling local privilege escalation. Includes target list and…

binary-exploitationexploitationpayload-development+3
1.0k5 years ago
MacroShop preview

MacroShop

GitHubkhr0x40sh/macroshop

Collection of scripts to aid in delivering payloads via Office Macros. Most are python. See http://khr0x40sh.wordpress.com for details.

payload-developmentpayload-generationpenetration-testing+2
40810 years ago
Invoke-CradleCrafter preview

Invoke-CradleCrafter

GitHubdanielbohannon/invoke-cradlecrafter

PowerShell Remote Download Cradle Generator & Obfuscator

command-and-controldefensive-toolspayload-development+3
8548 years ago
php_filter_chain_generator preview

php_filter_chain_generator

GitHubsynacktiv/php_filter_chain_generator

CLI to generate PHP filter chains for remote code execution via controlled include/require parameters. Produces complex iconv-based filter bypasses…

exploitationpayload-developmentpayload-generation+2
1.1k3 years ago
gh0st preview

gh0st

GitHubsin5678/gh0st

a open source remote administrator tool

command-and-controlpayload-developmentpenetration-testing+3
55813 years ago
meterssh preview

meterssh

GitHubtrustedsec/meterssh

MeterSSH is a way to take shellcode, inject it into memory then tunnel whatever port you want to over SSH to mask any type of communications as a…

command-and-controlexploitationpayload-development+4
5309 years ago
Meterpreter_Paranoid_Mode-SSL preview

Meterpreter_Paranoid_Mode-SSL

GitHubr00t-3xp10it/meterpreter_paranoid_mode-ssl

Meterpreter Paranoid Mode - SSL/TLS connections

command-and-controlexploitationpayload-development+4
2897 years ago
Windows_LPE_AFD_CVE-2023-21768 preview

Windows_LPE_AFD_CVE-2023-21768

GitHubchompie1337/windows_lpe_afd_cve-2023-21768

Local privilege escalation exploit for CVE-2023-21768 targeting Windows AFD driver. Elevates arbitrary process to SYSTEM using I/O Ring read/write…

binary-exploitationexploitationpayload-development+3
5053 years ago
xsser preview

xsser

GitHubvarbaek/xsser

From XSS to RCE 2.75 - Black Hat Europe Arsenal 2017 + Extras

exploitationpayload-developmentpenetration-testing+3
4236 years ago
ScreenshotBOF preview

ScreenshotBOF

GitHubcodextf2/screenshotbof

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.

command-and-controlpayload-developmentpenetration-testing+2
5081 month ago
spawn preview

spawn

GitHubboku7/spawn

Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks by spawning…

command-and-controlexploitationpayload-development+5
4643 years ago
pwn2own2020 preview

pwn2own2020

GitHubsslab-gatech/pwn2own2020

Compromising the macOS Kernel through Safari by Chaining Six Vulnerabilities

binary-exploitationexploitationpayload-development+4
4145 years ago
SerialKillerBypassGadgetCollection preview

SerialKillerBypassGadgetCollection

GitHubpwntester/serialkillerbypassgadgetcollection

Collection of bypass gadgets to extend and wrap ysoserial payloads

exploitationpayload-developmentpayload-generation+1
3894 years ago
bt2 preview

bt2

GitHubblazeinfosec/bt2

Blaze Telegram Backdoor Toolkit is a post-exploitation tool that leverages the infrastructure of Telegram as a C&C

command-and-controlpayload-developmentpenetration-testing+3
20610 years ago
Previous123…13Next